LABUBU Hack
What happened
On Dec-10-2024, the LABUBU token smart contract was exploited, resulting in a loss of approximately $120,000.
The core vulnerability lay in the token’s transfer logic, which allowed senders to increase their own balances simply by transferring tokens to themselves. The LABUBU contract did not properly handle transfers where the sender and recipient addresses were the same. As a result, a malicious user could repeatedly “send” tokens to their own address, artificially inflating their token balance without cost.
By exploiting this flawed mechanism, the attacker drained around $120,000 worth of tokens from the system before the vulnerability was discovered and addressed.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report nickfranklin.site
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.